CHAPTER 12 · Secrets and Bring-Your-Own-Key · 5 / 10
Resolution precedence: user beats operator
At call time, resolve which credential to use with a clear, single rule: user key if present, else operator key, else error. Concretely:
- Start with the operator (environment) credentials as the baseline.
- Load and decrypt the user's stored credentials; for each one present, override the baseline.
- The result is, per credential, the user's value if they have one, else the operator's, else null.
This single rule makes both deployment models work from one code path: a shared-operator-key deployment and a per-user-BYOK deployment are the same code, differing only in which values happen to be set. The resolved credentials flow down to wherever the external call is made, where a final fallback-or-throw guard produces a clear error if neither exists.
The same precedence applies to integration tokens (e.g. a third-party research API): per-user token first, operator token as fallback.